CVE-2026-4404
Received
Received - Intake
Hardcoded Credentials in GoHarbor Harbor Allow Unauthorized Access
Publication date: 2026-03-23
Last updated on: 2026-03-24
Assigner: CERT/CC
Description
Description
Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| goharbor | harbor | 2.15.0 |
| goharbor | harbor | to 2.16.0 (exc) |
| goharbor | harbor | to 2.15.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1393 | The product uses default passwords for potentially critical functionality. |
| CWE-798 | The product contains hard-coded credentials, such as a password or cryptographic key. |